โ† All CySA+ Test Flashcard Decks

CySA+ Difficulty Level Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CySA+ Difficulty Level flashcards as text
  1. Which NIST SP 800-61 document revision provides guidance on computer security incident handling?

    Answer: NIST SP 800-61 Rev 2

    NIST SP 800-61 Rev 2, 'Computer Security Incident Handling Guide,' is the primary federal reference for incident response.

  2. A candidate finds the CySA+ exam's cryptography questions challenging. Which topic should they review FIRST to improve in this area?

    Answer: PKI trust chains, certificate validation, and common cryptographic attacks

    CySA+ cryptography questions focus on PKI, certificate validation flows, and recognizing cryptographic attack patterns rather than deep mathematics.

  3. An analyst observes a spike in failed logon events (Event ID 4625) targeting a single account over 5 minutes. Which attack does this MOST indicate?

    Answer: Brute-force or password spray against a single account

    Repeated 4625 events against a single account in a short window indicates brute-force or targeted password guessing.

  4. Which artifact should an analyst collect FIRST when triaging a potentially compromised Linux host to preserve volatile data?

    Answer: Running process list and open network connections

    Running processes and active network connections are volatile and will be lost on reboot, making them the highest-priority collection.

  5. In the Diamond Model of intrusion analysis, which element describes the infrastructure used by the adversary?

    Answer: Infrastructure

    Infrastructure in the Diamond Model encompasses IP addresses, domains, and other resources the adversary uses to conduct the attack.

  6. A web application firewall is generating hundreds of SQL injection alerts daily, but manual review shows no successful exploits. What is the BEST next step?

    Answer: Tune the WAF rules and verify application input validation

    High alert volume with no successful exploitation suggests over-sensitive rules; tuning alongside validating input controls reduces noise without sacrificing coverage.

  7. Which CySA+ domain accounts for the LARGEST percentage of exam content according to the CompTIA exam objectives?

    Answer: Security Operations

    Security Operations carries the highest weight (33%) in the CySA+ CS0-003 exam objectives.